US2024106827A1PendingUtilityA1

Distributed access policies

Assignee: RED HAT INCPriority: Sep 26, 2022Filed: Sep 26, 2022Published: Mar 28, 2024
Est. expirySep 26, 2042(~16.2 yrs left)· nominal 20-yr term from priority
H04L 63/10H04L 63/0884H04L 63/20
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A first computing device of a plurality of computing devices in communication with one another via a communications channel receives, from a requesting computing device, an access request that identifies a subject, a resource identifier that identifies a resource, and an action, the first computing device having a set of access policies, each access policy corresponding to a particular resource of a plurality of resources. The first computing device determines that the resource identifier identifies a resource that is not governed by an access policy in the set of access policies. The first computing device sends, to the communications channel, the access request. The first computing device receives an access request decision from a second computing device of the plurality of computing devices, and the first computing device grants or denies access to the resource by the user based on the access request decision.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by a first computing device of a plurality of computing devices in communication with one another via a communications channel, from a requesting computing device, an access request that identifies a subject, a resource identifier that identifies a resource, and an action, the first computing device having a set of access policies, each access policy corresponding to a particular resource of a plurality of resources;   determining, by the first computing device, that the resource identifier identifies a resource that is not governed by an access policy in the set of access policies;   sending, by the first computing device to the communications channel, the access request;   receiving, by the first computing device, an access request decision from a second computing device of the plurality of computing devices; and   granting or denying access to the resource by the subject based on the access request decision.   
     
     
         2 . The method of  claim 1  wherein the communications channel comprises a publish/subscribe message bus, and further comprising subscribing, by the first computing device, to the publish/subscribe message bus. 
     
     
         3 . The method of  claim 1  wherein the resource is a resource controlled by the first computing device, and wherein the access request decision is to grant access to the resource. 
     
     
         4 . The method of  claim 1  wherein the resource is controlled by a third computing device, and wherein access is granted to the resource, and further comprising:
 providing, by the first computing device to the requesting computing device, authentication information that, when presented to the third computing device, validates to the third computing device that the requesting computing device has been granted access. 
 
     
     
         5 . The method of  claim 1  wherein the resource is controlled by a third computing device, and wherein access is granted to the resource, and further comprising:
 providing, by the first computing device to the third computing device, information identifying the requesting computing device and an indication that the requesting computing device has been granted access to the resource. 
 
     
     
         6 . The method of  claim 1  further comprising:
 broadcasting, by the first computing device via the communications channel, information that identifies the resources governed by the set of access policies. 
 
     
     
         7 . The method of  claim 1  further comprising:
 receiving, by the first computing device, a plurality of messages, the plurality of messages identifying, for at least some of the other computing devices of the plurality of computing devices, resources governed by the other computing devices; and 
 generating, by the first computing device, a data structure that identifies the resources governed by the other computing devices, and for each resource, the corresponding computing device that governs access to the resource. 
 
     
     
         8 . The method of  claim 1  wherein the resource is controlled by the second computing device, and further comprising:
 sending, by the first computing device to the second computing device, the action; 
 receiving, by the first computing device from the second computing device, a reply; and 
 sending, by the first computing device to the requesting computing device, the reply. 
 
     
     
         9 . A computing device, comprising:
 a memory; and   a processor device coupled to the memory to:
 receive, via a communications channel, from a requesting computing device, an access request that identifies a subject, a resource identifier that identifies a resource, and an action, the first computing device having a set of access policies, each access policy corresponding to a particular resource of a plurality of resources; 
 determine that the resource identifier identifies a resource that is not governed by an access policy in the set of access policies; 
 send, to the communications channel, the access request; 
 receive an access request decision from a second computing device of the plurality of computing devices; and 
 grant or deny access to the resource by the user based on the access request decision. 
   
     
     
         10 . The computing device of  claim 9  wherein the resource is a resource controlled by the first computing device, and wherein the access request decision is to grant access to the resource. 
     
     
         11 . The computing device of  claim 9  wherein the resource is controlled by a third computing device, and wherein access is granted to the resource, and wherein the processor device is further to:
 provide, to the requesting computing device, authentication information that, when presented to the third computing device, validates to the third computing device that the requesting computing device has been granted access. 
 
     
     
         12 . The computing device of  claim 9  wherein the resource is controlled by a third computing device, and wherein access is granted to the resource, and wherein the processor device is further to:
 provide, to the third computing device, information identifying the requesting computing device and an indication that the requesting computing device has been granted access to the resource. 
 
     
     
         13 . The computing device of  claim 9  wherein the processor device is further to:
 broadcast, via the communications channel, information that identifies the resources governed by the set of access policies. 
 
     
     
         14 . The computing device of  claim 9  wherein the processor device is further to:
 receive a plurality of messages, the plurality of messages identifying, for at least some of the other computing devices of the plurality of computing devices, resources governed by the other computing devices; and 
 generate a data structure that identifies the resources governed by the other computing devices, and for each resource, the corresponding computing device that governs access to the resource. 
 
     
     
         15 . The computing device of  claim 9  wherein the resource is controlled by the second computing device, and wherein the processor device is further to:
 send, to the second computing device, the action; 
 receive, from the second computing device, a reply; and 
 send, to the requesting computing device, the reply. 
 
     
     
         16 . A non-transitory computer-readable storage medium that includes executable instructions to cause a processor device to:
 receive, via a communications channel, from a requesting computing device, an access request that identifies a subject, a resource identifier that identifies a resource, and an action, the first computing device having a set of access policies, each access policy corresponding to a particular resource of a plurality of resources;   determine that the resource identifier identifies a resource that is not governed by an access policy in the set of access policies;   send, to the communications channel, the access request;   receive an access request decision from a second computing device of the plurality of computing devices; and   grant or deny access to the resource by the user based on the access request decision.   
     
     
         17 . The non-transitory computer-readable storage medium of  claim 16  wherein the resource is a resource controlled by the first computing device, and wherein the access request decision is to grant access to the resource. 
     
     
         18 . The non-transitory computer-readable storage medium of  claim 16  wherein the resource is controlled by a third computing device, and wherein access is granted to the resource, and wherein the processor device is further to:
 provide, to the requesting computing device, authentication information that, when presented to the third computing device, validates to the third computing device that the requesting computing device has been granted access. 
 
     
     
         19 . The non-transitory computer-readable storage medium of  claim 16  wherein the resource is controlled by a third computing device, and wherein access is granted to the resource, and wherein the processor device is further to:
 provide, to the third computing device, information identifying the requesting computing device and an indication that the requesting computing device has been granted access to the resource. 
 
     
     
         20 . The non-transitory computer-readable storage medium of  claim 16  wherein the processor device is further to:
 broadcast, via the communications channel, information that identifies the resources governed by the set of access policies.

Join the waitlist — get patent alerts

Track US2024106827A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.